A flaw was found in the kubevirt-csi component of...
High severity
Unreviewed
Published
Mar 7, 2024
to the GitHub Advisory Database
•
Updated May 8, 2024
Description
Published by the National Vulnerability Database
Mar 7, 2024
Published to the GitHub Advisory Database
Mar 7, 2024
Last updated
May 8, 2024
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.
References